All of lore.kernel.org
 help / color / mirror / Atom feed
* Portscan??
@ 2002-11-12 11:57 romaniuc
  2002-11-12 12:13 ` how to drop MP3 and other Downloads hare ram
  0 siblings, 1 reply; 9+ messages in thread
From: romaniuc @ 2002-11-12 11:57 UTC (permalink / raw)
  To: netfilter


Hi all,

	I´m trying to detect and block portscan.... and Im using 
rules below.....
	It´s doesn´t work... I use a lot of portscan and no one have been 
detected;;; what is wrong???

Thanks

RULES.....


$IPTABLES -F NOVA_CONEXAO
$IPTABLES -X NOVA_CONEXAO > /dev/null

## NAT
$IPTABLES -t nat -F

$IPTABLES -N NOVA_CONEXAO

## New packets
$IPTABLES -A INPUT -i $EXTIF -p ! icmp -m state --state NEW -j 
NOVA_CONEXAO

## PortScanners - Detection
#$IPTABLES -A NOVA_CONEXAO -j LOG --log-prefix 
"############################"
## NMAP FIN/URG/PSH
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags ALL FIN,URG,PSH -m limit 
--limit 2/s -j LOG --log-prefix "(Nmap) Stealth XMAS Scan: "
# SYN/RST
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags SYN,RST SYN,RST -m limit 
--limit 2/s -j LOG --log-prefix "SYN/RST Scan: "

# SYN/FIN (probably)
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags SYN,FIN SYN,FIN -m limit 
--limit 2/s -j LOG --log-prefix "SYN/FIN Scan(?): "
# NMAP FIN Stealth
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags ALL FIN -m limit --limit 2/s 
-j LOG --log-prefix "(Nmap) Stealth FYN Scan: "
# ALL/ALL Scan
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags ALL ALL -m limit --limit 2/s 
-j LOG --log-prefix "ALL/ALL Scan: "
# NMAP Null Scan (probably)
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags ALL NONE -m limit --limit 2/s 
-j LOG --log-prefix "(Nmap) Stealth Null Scan(?): "
## Now Dropping
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags ALL FIN,URG,PSH -j DROP
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags SYN,RST SYN,RST -j DROP
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags SYN,FIN SYN,FIN -j DROP
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags ALL FIN -j DROP
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags ALL ALL -j DROP
$IPTABLES -A NOVA_CONEXAO -p tcp --tcp-flags ALL NONE -j DROP

################################
## Now my rules..... INPUT



^ permalink raw reply	[flat|nested] 9+ messages in thread

* how to drop MP3 and other Downloads
  2002-11-12 11:57 Portscan?? romaniuc
@ 2002-11-12 12:13 ` hare ram
  2002-11-12 12:30   ` Alex Bennee
                     ` (3 more replies)
  0 siblings, 4 replies; 9+ messages in thread
From: hare ram @ 2002-11-12 12:13 UTC (permalink / raw)
  To: netfilter; +Cc: isp-linux

Hi all

i have small application here like
how do the drop all downloads more than 1MB from
the day time
and rest of the time open for all

any suggestion is greate
thanks
hare



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: how to drop MP3 and other Downloads
  2002-11-12 12:13 ` how to drop MP3 and other Downloads hare ram
@ 2002-11-12 12:30   ` Alex Bennee
  2002-11-12 12:32   ` Alex Bennee
                     ` (2 subsequent siblings)
  3 siblings, 0 replies; 9+ messages in thread
From: Alex Bennee @ 2002-11-12 12:30 UTC (permalink / raw)
  To: hareram; +Cc: netfilter, isp-linux

hare ram said:
> Hi all
>
> i have small application here like
> how do the drop all downloads more than 1MB from
> the day time
> and rest of the time open for all
>
> any suggestion is greate
> thanks
> hare

You can try the connytes patch
http://libre.act-europe.fr/gvd/gvd-1.2.5-src.tgz
Alex
www.bennee.com/~alex/




^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: how to drop MP3 and other Downloads
  2002-11-12 12:13 ` how to drop MP3 and other Downloads hare ram
  2002-11-12 12:30   ` Alex Bennee
@ 2002-11-12 12:32   ` Alex Bennee
  2002-11-12 12:43   ` Antony Stone
  2002-11-13  9:19   ` Dharmendra.T
  3 siblings, 0 replies; 9+ messages in thread
From: Alex Bennee @ 2002-11-12 12:32 UTC (permalink / raw)
  To: hareram; +Cc: netfilter, isp-linux

hare ram said:
> Hi all
>
> i have small application here like
> how do the drop all downloads more than 1MB from
> the day time
> and rest of the time open for all

That of course was not the connbytes patch. You can find it at
http://luxik.cdi.cz/~devik/connbytes/.

You may need some sort of crontab to change the rules as you go. You can
also use connbytes with the --mark to move all long lived downloads to a
lower tc class if your doing traffic shaping.

Alex
www.bennee.com/~alex/




^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: how to drop MP3 and other Downloads
  2002-11-12 12:13 ` how to drop MP3 and other Downloads hare ram
  2002-11-12 12:30   ` Alex Bennee
  2002-11-12 12:32   ` Alex Bennee
@ 2002-11-12 12:43   ` Antony Stone
  2002-11-12 14:05     ` hare ram
  2002-11-13  9:19   ` Dharmendra.T
  3 siblings, 1 reply; 9+ messages in thread
From: Antony Stone @ 2002-11-12 12:43 UTC (permalink / raw)
  To: netfilter

On Tuesday 12 November 2002 12:13 pm, hare ram wrote:

> Hi all
>
> i have small application here like
> how do the drop all downloads more than 1MB from
> the day time
> and rest of the time open for all

I don't see that netfilter can know a download is going to be more than 
1Mbyte before it's already seen a million bytes downloaded...

Antony.

-- 

There are two possible outcomes.

If the result confirms the hypothesis, then you've made a measurement.
If the result is contrary to the hypothesis, then you've made a discovery.

 - Enrico Fermi


^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: how to drop MP3 and other Downloads
  2002-11-12 12:43   ` Antony Stone
@ 2002-11-12 14:05     ` hare ram
  0 siblings, 0 replies; 9+ messages in thread
From: hare ram @ 2002-11-12 14:05 UTC (permalink / raw)
  To: Antony Stone, netfilter

hi some one guided in the news group

----
That of course was not the connbytes patch. You can find it at
http://luxik.cdi.cz/~devik/connbytes/.

You may need some sort of crontab to change the rules as you go. You can
also use connbytes with the --mark to move all long lived downloads to a
lower tc class if your doing traffic shaping.
------


what you think about this

thanks
hare
----- Original Message -----
From: "Antony Stone" <Antony@Soft-Solutions.co.uk>
To: <netfilter@lists.netfilter.org>
Sent: Tuesday, November 12, 2002 6:13 PM
Subject: Re: how to drop MP3 and other Downloads


> On Tuesday 12 November 2002 12:13 pm, hare ram wrote:
>
> > Hi all
> >
> > i have small application here like
> > how do the drop all downloads more than 1MB from
> > the day time
> > and rest of the time open for all
>
> I don't see that netfilter can know a download is going to be more than
> 1Mbyte before it's already seen a million bytes downloaded...
>
> Antony.
>
> --
>
> There are two possible outcomes.
>
> If the result confirms the hypothesis, then you've made a measurement.
> If the result is contrary to the hypothesis, then you've made a discovery.
>
>  - Enrico Fermi
>
>



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: how to drop MP3 and other Downloads
@ 2002-11-13  9:07 Andrew Magnus
  2002-11-13  9:40 ` Alex Bennee
  0 siblings, 1 reply; 9+ messages in thread
From: Andrew Magnus @ 2002-11-13  9:07 UTC (permalink / raw)
  To: netfilter


This, of course, brings up a question I've been thinking about.

Is there a patch that will allow iptables to read into the header for the 
presentation layer to filter out, for example, MP3s being downloaded?

Thanks.



>From: "hare ram" <hareram@sol.net.in>
>Reply-To: "hare ram" <hareram@sol.net.in>
>To: "Antony Stone" 
><Antony@Soft-Solutions.co.uk>,<netfilter@lists.netfilter.org>
>Subject: Re: how to drop MP3 and other Downloads
>Date: Tue, 12 Nov 2002 19:35:14 +0530
>
>hi some one guided in the news group
>
>----
>That of course was not the connbytes patch. You can find it at
>http://luxik.cdi.cz/~devik/connbytes/.
>
>You may need some sort of crontab to change the rules as you go. You can
>also use connbytes with the --mark to move all long lived downloads to a
>lower tc class if your doing traffic shaping.
>------
>
>
>what you think about this
>
>thanks
>hare
>----- Original Message -----
>From: "Antony Stone" <Antony@Soft-Solutions.co.uk>
>To: <netfilter@lists.netfilter.org>
>Sent: Tuesday, November 12, 2002 6:13 PM
>Subject: Re: how to drop MP3 and other Downloads
>
>
> > On Tuesday 12 November 2002 12:13 pm, hare ram wrote:
> >
> > > Hi all
> > >
> > > i have small application here like
> > > how do the drop all downloads more than 1MB from
> > > the day time
> > > and rest of the time open for all
> >
> > I don't see that netfilter can know a download is going to be more than
> > 1Mbyte before it's already seen a million bytes downloaded...
> >
> > Antony.
> >
> > --
> >
> > There are two possible outcomes.
> >
> > If the result confirms the hypothesis, then you've made a measurement.
> > If the result is contrary to the hypothesis, then you've made a 
>discovery.
> >
> >  - Enrico Fermi
> >
> >


_________________________________________________________________
MSN 8 helps eliminate e-mail viruses. Get 2 months FREE*. 
http://join.msn.com/?page=features/virus



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: how to drop MP3 and other Downloads
  2002-11-12 12:13 ` how to drop MP3 and other Downloads hare ram
                     ` (2 preceding siblings ...)
  2002-11-12 12:43   ` Antony Stone
@ 2002-11-13  9:19   ` Dharmendra.T
  3 siblings, 0 replies; 9+ messages in thread
From: Dharmendra.T @ 2002-11-13  9:19 UTC (permalink / raw)
  To: hare ram, netfilter; +Cc: isp-linux

Hi Ram
 YOu have to configure this in the proxy server. If you are natting the 
requests then you have to install iproute along with iptables and schedule 
the process accordingly.

Regards,
Dharmendra.T
Linux Security Expert
www.nsecure.net
dharmu@nsecure.net
On Tuesday 12 November 2002 17:43, hare ram wrote:
> Hi all
>
> i have small application here like
> how do the drop all downloads more than 1MB from
> the day time
> and rest of the time open for all
>
> any suggestion is greate
> thanks
> hare

-- 



^ permalink raw reply	[flat|nested] 9+ messages in thread

* Re: how to drop MP3 and other Downloads
  2002-11-13  9:07 Andrew Magnus
@ 2002-11-13  9:40 ` Alex Bennee
  0 siblings, 0 replies; 9+ messages in thread
From: Alex Bennee @ 2002-11-13  9:40 UTC (permalink / raw)
  To: xanadian9; +Cc: netfilter

Andrew Magnus said:
>
> This, of course, brings up a question I've been thinking about.
>
> Is there a patch that will allow iptables to read into the header for
> the  presentation layer to filter out, for example, MP3s being
> downloaded?

The fact you want something at the transport layer to be looking at data at
the application layer tells you something is wrong with the approach. This
is what proxies are for.

>
>>From: "hare ram" <hareram@sol.net.in>
>>Reply-To: "hare ram" <hareram@sol.net.in>
>>To: "Antony Stone"
>><Antony@Soft-Solutions.co.uk>,<netfilter@lists.netfilter.org>
>>Subject: Re: how to drop MP3 and other Downloads
>>Date: Tue, 12 Nov 2002 19:35:14 +0530
>>
>>hi some one guided in the news group
>>
>>----
>>That of course was not the connbytes patch. You can find it at
>>http://luxik.cdi.cz/~devik/connbytes/.
>>
>>You may need some sort of crontab to change the rules as you go. You
>>can also use connbytes with the --mark to move all long lived downloads
>>to a lower tc class if your doing traffic shaping.
>>------
>>
>>
>>what you think about this
>>
>>thanks
>>hare
>>----- Original Message -----
>>From: "Antony Stone" <Antony@Soft-Solutions.co.uk>
>>To: <netfilter@lists.netfilter.org>
>>Sent: Tuesday, November 12, 2002 6:13 PM
>>Subject: Re: how to drop MP3 and other Downloads
>>
>>
>> > On Tuesday 12 November 2002 12:13 pm, hare ram wrote:
>> >
>> > > Hi all
>> > >
>> > > i have small application here like
>> > > how do the drop all downloads more than 1MB from
>> > > the day time
>> > > and rest of the time open for all
>> >
>> > I don't see that netfilter can know a download is going to be more
>> > than 1Mbyte before it's already seen a million bytes downloaded...
>> >
>> > Antony.
>> >
>> > --
>> >
>> > There are two possible outcomes.
>> >
>> > If the result confirms the hypothesis, then you've made a
>> > measurement. If the result is contrary to the hypothesis, then
>> > you've made a
>>discovery.
>> >
>> >  - Enrico Fermi
>> >
>> >
>
>
> _________________________________________________________________
> MSN 8 helps eliminate e-mail viruses. Get 2 months FREE*.
> http://join.msn.com/?page=features/virus


Alex
www.bennee.com/~alex/




^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2002-11-13  9:40 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-11-12 11:57 Portscan?? romaniuc
2002-11-12 12:13 ` how to drop MP3 and other Downloads hare ram
2002-11-12 12:30   ` Alex Bennee
2002-11-12 12:32   ` Alex Bennee
2002-11-12 12:43   ` Antony Stone
2002-11-12 14:05     ` hare ram
2002-11-13  9:19   ` Dharmendra.T
  -- strict thread matches above, loose matches on Subject: below --
2002-11-13  9:07 Andrew Magnus
2002-11-13  9:40 ` Alex Bennee

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.